Security Bulletin

CVE-2026-67401: SQL Injection in cPanel’s EmailTrack Puts Shared Hosting Environments at Risk

2 min read Updated

A critical SQL injection vulnerability has been identified in cPanel & WHM’s EmailTrack functionality. The vulnerability was disclosed by cPanel on September 8, 2026, affecting every supported release line. It allows an authenticated cPanel account holder with mail related privileges to ultimately achieve root-level code execution on the underlying host.

 cPanel & WHM EmailTrack SQL Injection / Root Code Execution Vulnerability

CVE-2026-67401 is a SQL injection vulnerability in EmailTrack, the cPanel & WHM module that tracks email statistics. A hosting customer gets a standard cPanel account with a defined set of privileges, including mail management, while the provider controls the full machine through WHM as root. EmailTrack’s SQL injection collapses that separation. An account holder with mail-related privileges can exploit the EmailTrack functionality through SQL injection.

Successful exploitation allows an authenticated cPanel account holder to create arbitrary files on the server. According to cPanel, successful exploitation ultimately leads to code execution as a root user giving an attacker full control of the server.

cPanel’s advisory doesn’t publish the specific request parameters, the SQL statement, or the exact mechanics connecting file creation to root execution.

What CVE-2026-67401 Affects

All supported cPanel & WHM versions are affected. cPanel has shipped patches for each line: 11.110 (fixed in 11.110.0.143), 11.134 (fixed in 11.134.0.55), 11.136 (fixed in 11.136.0.39), 11.138 (fixed in 11.138.0.4), and WP Squared (fixed in 11.138.1.9). Confirm the release line and current version on each managed server against this list before assuming a server is covered.

CVE-2026-67401: Patch and Remediation Steps

Work through the following steps in sequence to remediate exposure:

  • Inventory every cPanel & WHM or WP2 server under management before touching anything. List the servers, then check the version and release line running on each one.
  • Update to the fixed build for that release line. Run /usr/local/cpanel/scripts/upcp –force, or trigger the update from WHM directly.
  • Prioritize multi-tenant and shared hosting environments first, as multiple accounts may have mail related privileges required to exploit this vulnerability, potentially increasing the impact of a compromise.
  • Audit mail account privileges across tenants. The trigger point is a standard mail account, so organization should review affected account and application activity in addition to perimeter-level checks
  • Check for signs of prior compromise on any server that was running an unpatched version. Review authentication logs, admin action history, and unexpected file changes. Patching closes the hole going forward. It doesn’t confirm nothing happened before the patch went in.

AppTrana Coverage for CVE-2026-67401

AppTrana customers have been protected against exploitation of CVE-2026-67401 from day zero. AppTrana provides autonomous protection by default, inspecting requests to the EmailTrack module and blocking payloads that match known SQL injection exploitation patterns. This gives teams a protective layer while they patch affected cPanel & WHM instances and audit for signs of prior compromise.

Bhargavi Pallati

Bhargavi Pallati is a Security Researcher at Indusface with experience in threat analysis, web application security, and detection engineering. She has a strong background as a Security Analyst and has worked extensively on vulnerability assessment and coverage verification. Bhargavi focuses on analyzing emerging attack patterns, strengthening application-level defenses, and improving security controls through continuous research and learning.